zpa_list_segment_groups()zpa_list_application_segments()```text
**For identity conditions:**
```textget_zpa_scim_group(search="<group_name>")get_zpa_saml_attribute(search="<attribute_name>")```text
**For posture profiles:**
```textget_zpa_posture_profile(search="<profile_name>")```text
---
### Step 3: Create the Rule
```textzpa_create_timeout_policy_rule( name="<rule_name>", action_type="RE_AUTH", reauth_timeout="<session_timeout>", reauth_idle_timeout="<idle_timeout>", description="<description>", conditions=<conditions_payload>)```text
---
### Step 4: Verify
```textzpa_get_timeout_policy_rule(rule_id="<returned_rule_id>")```text
---
## Ready-to-Use Examples
### Example 1: Standard Timeout for a Segment Group
Set 8-hour session timeout and 30-minute idle timeout for internal applications.
**Step 1: Find the segment group**
```textzpa_list_segment_groups()```text
**Step 2: Create rule**
```textzpa_create_timeout_policy_rule( name="Standard Timeout - Internal Apps", action_type="RE_AUTH", reauth_timeout="8 Hours", reauth_idle_timeout="30 Minutes", description="Standard session and idle timeouts for internal applications", conditions=[ { "operator": "OR", "operands": [ { "object_type": "APP_GROUP", "values": ["<internal_apps_segment_group_id>"] } ] } ])```text
---
### Example 2: Strict Timeout for Sensitive Applications
Short session timeout (4 hours) and aggressive idle timeout (10 minutes) for sensitive apps.
```textzpa_create_timeout_policy_rule( name="Strict Timeout - Sensitive Apps", action_type="RE_AUTH", reauth_timeout="4 Hours", reauth_idle_timeout="10 Minutes", description="Short timeouts for sensitive/high-security applications", conditions=[ { "operator": "OR", "operands": [ { "object_type": "APP_GROUP", "values": ["<sensitive_apps_segment_group_id>"] } ] } ])```text
---
### Example 3: Contractor-Specific Timeout
Contractors must re-authenticate every 4 hours with a 15-minute idle timeout.
**Step 1: Look up contractor group**
```textget_zpa_scim_group(search="Contractors")```text
**Step 2: Create rule**
```textzpa_create_timeout_policy_rule( name="Contractor Timeout", action_type="RE_AUTH", reauth_timeout="4 Hours", reauth_idle_timeout="15 Minutes", description="Shorter session for contractor accounts", conditions=[ { "operator": "OR", "operands": [ { "object_type": "SCIM_GROUP", "entry_values": [ {"lhs": "<idp_id>", "rhs": "<contractors_scim_group_id>"} ] } ] } ])```text
---
### Example 4: Long Timeout with SAML + Segment Group
Allow a 10-day session for specific SAML-identified users on a specific segment group.
**Step 1: Look up IDs**
```textget_zpa_saml_attribute(search="Email_Users")zpa_list_segment_groups()```text
**Step 2: Create rule**
```textzpa_create_timeout_policy_rule( name="Extended Timeout - VIP Users", action_type="RE_AUTH", reauth_timeout="10 Days", reauth_idle_timeout="1 Hours", description="Extended session for VIP users accessing standard apps", conditions=[ { "operator": "OR", "operands": [ { "object_type": "APP_GROUP", "values": ["<segment_group_id>"] } ] }, { "operator": "OR", "operands": [ { "object_type": "SAML", "entry_values": [ {"lhs": "<saml_email_attr_id>", "rhs": "[email protected]"}, {"lhs": "<saml_email_attr_id>", "rhs": "[email protected]"} ] } ] } ])```text
**Logic:** User must be accessing apps in the segment group AND have a matching SAML email.
---
### Example 5: Platform-Specific Timeout
Mobile devices (Android/iOS) get shorter timeouts than desktops.
**Mobile rule (stricter):**
```textzpa_create_timeout_policy_rule( name="Mobile Timeout - Short", action_type="RE_AUTH", reauth_timeout="4 Hours", reauth_idle_timeout="15 Minutes", description="Shorter timeouts for mobile devices", conditions=[ { "operator": "OR", "operands": [ { "object_type": "PLATFORM", "entry_values": [ {"lhs": "android", "rhs": "true"}, {"lhs": "ios", "rhs": "true"} ] } ] } ])```text
**Desktop rule (more relaxed):**
```textzpa_create_timeout_policy_rule( name="Desktop Timeout - Standard", action_type="RE_AUTH", reauth_timeout="10 Days", reauth_idle_timeout="1 Hours", description="Standard timeouts for desktop devices", conditions=[ { "operator": "OR", "operands": [ { "object_type": "PLATFORM", "entry_values": [ {"lhs": "mac", "rhs": "true"}, {"lhs": "windows", "rhs": "true"}, {"lhs": "linux", "rhs": "true"} ] } ] } ])```text
---
### Example 6: Posture-Based Timeout
Devices that pass a posture check get a longer timeout; non-compliant devices get a shorter one.
**Step 1: Look up posture profile**
```textget_zpa_posture_profile(search="CrowdStrike_ZTA")```text
**Compliant devices (longer timeout):**
```textzpa_create_timeout_policy_rule( name="Compliant Device Timeout", action_type="RE_AUTH", reauth_timeout="30 Days", reauth_idle_timeout="2 Hours", description="Extended timeout for posture-compliant devices", conditions=[ { "operator": "OR", "operands": [ { "object_type": "POSTURE", "entry_values": [ {"lhs": "<posture_udid>", "rhs": "true"} ] } ] } ])```text
**Non-compliant devices (shorter timeout):**
```textzpa_create_timeout_policy_rule( name="Non-Compliant Device Timeout", action_type="RE_AUTH", reauth_timeout="1 Hours", reauth_idle_timeout="10 Minutes", description="Aggressive timeout for non-compliant devices", conditions=[ { "operator": "OR", "operands": [ { "object_type": "POSTURE", "entry_values": [ {"lhs": "<posture_udid>", "rhs": "false"} ] } ] } ])```text
---
### Example 7: Combined Conditions -- Group + App + Platform
Engineering team accessing sensitive apps from Linux gets a specific timeout.
```textzpa_create_timeout_policy_rule( name="Engineering Linux Timeout", action_type="RE_AUTH", reauth_timeout="12 Hours", reauth_idle_timeout="45 Minutes", description="Custom timeout for Engineering on Linux accessing sensitive apps", conditions=[ { "operator": "OR", "operands": [ { "object_type": "APP_GROUP", "values": ["<sensitive_apps_segment_group_id>"] } ] }, { "operator": "OR", "operands": [ { "object_type": "SCIM_GROUP", "entry_values": [ {"lhs": "<idp_id>", "rhs": "<engineering_group_id>"} ] } ] }, { "operator": "OR", "operands": [ { "object_type": "PLATFORM", "entry_values": [ {"lhs": "linux", "rhs": "true"} ] } ] } ])```text
---
## Timeout Strategy Guide
| Use Case | reauth_timeout | reauth_idle_timeout | Rationale ||---|---|---|---|| Standard office apps | 8-10 Hours | 30-60 Minutes | Covers a workday without constant re-auth || Sensitive/compliance apps | 2-4 Hours | 10-15 Minutes | Frequent re-auth for high-security apps || Contractors / third parties | 4 Hours | 15 Minutes | Reduced trust, tighter controls || Mobile devices | 4-8 Hours | 15-30 Minutes | Higher risk of device loss || Desktop on corporate network | 10-30 Days | 1-2 Hours | Low risk, high convenience || Non-compliant devices | 1-2 Hours | 10 Minutes | Encourage compliance || Development/test environments | 30 Days / Never | 2 Hours | Minimize developer friction |
---
## Edge Cases
### No Conditions (Global Default)
A rule with no conditions applies as the default timeout for all users and applications:
```textzpa_create_timeout_policy_rule( name="Global Default Timeout", action_type="RE_AUTH", reauth_timeout="8 Hours", reauth_idle_timeout="30 Minutes", conditions=[])```text
### Never Expire
For development or test environments where re-authentication is disruptive:
```textzpa_create_timeout_policy_rule( name="Dev Environment - No Timeout", action_type="RE_AUTH", reauth_timeout="Never", reauth_idle_timeout="Never", conditions=[ { "operator": "OR", "operands": [ { "object_type": "APP_GROUP", "values": ["<dev_segment_group_id>"] } ] } ])```text
Not recommended for production applications.
### Listing Existing Timeout Rules (opt-in)
Do **not** pre-list timeout rules before every create. New ZPA timeoutrules are appended at the end of the policy by default; pre-listingadds a round trip, gives no useful information for the typical case,and invites fan-out retries when the list comes back empty on a freshtenant.
Run the listing **only** when the admin explicitly asks about ordering,duplicate names, or wants to inspect existing rules:
```textzpa_list_timeout_policy_rules()```text
---
## Quick Reference
**Tools used:**
- `zpa_list_segment_groups()` -- find segment group IDs- `zpa_list_application_segments()` -- find application segment IDs- `get_zpa_scim_group(search)` -- look up SCIM group IDs- `get_zpa_saml_attribute(search)` -- look up SAML attribute IDs- `get_zpa_posture_profile(search)` -- look up posture profile UDIDs- `zpa_create_timeout_policy_rule(name, action_type, reauth_timeout, reauth_idle_timeout, conditions)` -- create the rule (no pre-flight needed)- `zpa_list_timeout_policy_rules()` -- **only** when the admin explicitly asks about ordering or wants to inspect existing rules- `zpa_get_timeout_policy_rule(rule_id)` -- verify the rule
**Timeout format:** `"<number> Minutes"`, `"<number> Hours"`, `"<number> Days"`, `"Never"`
**Action:** `RE_AUTH` (only supported action)
**Condition logic:**
- Multiple condition blocks = AND (all must match)- Multiple entry_values within a block = OR (any can match)- Separate condition blocks per object type